CVE-2022-49277
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49277 is a memory leak vulnerability discovered in the Linux kernel's JFFS2 (Journalling Flash File System version 2) filesystem component. The vulnerability was identified in the jffs2_do_mount_fs() function, where resources allocated in jffs2_sum_init() are not properly released when jffs2_build_filesystem() returns an error (Kernel Git).

Technical details

The vulnerability occurs in the filesystem mounting process when jffs2_build_filesystem() in jffs2_do_mount_fs() returns an error. The issue manifests as unreferenced memory objects, specifically one of size 64 bytes and another of size 65536 bytes, which are allocated but not properly freed. The memory leak is triggered during the mount operation and can be observed through kmemleak reports (NVD).

Impact

The memory leak can lead to gradual system memory consumption over time when mounting and unmounting JFFS2 filesystems. While this doesn't present an immediate security risk, it could potentially lead to system performance degradation or stability issues if the leaked memory accumulates significantly (Ubuntu Security).

Mitigation and workarounds

The issue has been fixed by adding a call to jffs2_sum_exit() to release the allocated resources when an error occurs. The fix was implemented in the Linux kernel through a patch that modifies the error handling path in jffs2_do_mount_fs(). Users should update to a patched kernel version that includes this fix (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-cross-headers
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-modules-core
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management